PT-2025-1628 · Tcas Ii · Tcas Ii
Alessio Merlo
+4
·
Published
2025-01-22
·
Updated
2025-07-25
·
CVE-2024-11166
CVSS v4.0
7.1
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F
Description
The issue allows an attacker to impersonate a ground station and issue a Comm-A Identity Request. This action can set the Sensitivity Level Control (SLC) to the lowest setting and disable the Resolution Advisory (RA), leading to a denial-of-service condition.
Recommendations
For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, consider disabling the Comm-A Identity Request feature until a patch or update is available to prevent an attacker from setting the SLC to the lowest setting and disabling the RA. Restrict access to the system to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tcas Ii